Network Operator is degraded after adding a custom PKI

Solution Verified - Updated -


  • The Network Operator becomes degraded after adding a custom PKI post-installation. The following error is displayed:

    The configuration is invalid for proxy 'cluster' (failed to validate trust bundle for proxy trustedCA 'custom-ca': failed parsing certificate data from ConfigMap "custom-ca": failed to parse certificate PEM).
  • openssl verifyshows the certificate verification failed with error 18:

    error 18 at 0 depth lookup: self signed certificate
    error stdin: verification failed


  • OpenShift Container Platform 4 (OCP)
  • Red Hat Enterprise Linux CoreOS (RHCOS)

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content